CVE-2018-9086

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
16/11/2018
Last modified:
24/08/2020

Description

In some Lenovo ThinkServer-branded servers, a command injection vulnerability exists in the BMC firmware download command. This allows a privileged user to download and execute arbitrary code inside the BMC. This can only be exploited by authorized privileged users.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:lenovo:thinkserver_rd340_firmware:*:*:*:*:*:*:*:* 64.00 (excluding)
cpe:2.3:h:lenovo:thinkserver_rd340:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkserver_rd440_firmware:*:*:*:*:*:*:*:* 64.00 (excluding)
cpe:2.3:h:lenovo:thinkserver_rd440:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkserver_rd640_firmware:*:*:*:*:*:*:*:* 64.00 (excluding)
cpe:2.3:h:lenovo:thinkserver_rd640:-:*:*:*:*:*:*:*
cpe:2.3:o:lenovo:thinkserver_td340_firmware:*:*:*:*:*:*:*:* 60.00 (excluding)
cpe:2.3:h:lenovo:thinkserver_td340:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools